Junglewise Threat Intelligence

CVE-2026-4767: TR7 Cyber Defense WAF-ASP missing authentication for critical function

CVE-2026-4767 · Severity: critical · CVSS 9.8 · Published 2026-07-02

Executive brief

A critical security flaw has been identified in the TR7 WAF-ASP, a web application firewall designed to protect corporate websites and applications from cyberattacks. Due to a failure to require proper login credentials for sensitive functions, an unauthorized person could gain full control over the security appliance. This could lead to the theft of sensitive data, disruption of web services, or the complete bypass of existing security measures.

Technical details

A vulnerability classified as CWE-306 (Missing Authentication for Critical Function) exists in TR7 Cyber Defense Inc. WAF-ASP. The flaw allows a remote, unauthenticated attacker to access and execute critical administrative functions over the network without providing valid credentials. This is due to insufficient access control checks on sensitive endpoints within the WAF management interface. Successful exploitation grants the attacker full control over the appliance, potentially leading to complete compromise of confidentiality, integrity, and availability. The issue is addressed in version v1.4.0.117.

Affected products

  • TR7 Cyber Defense Inc. WAF-ASP v1.0.324.900 to v1.4.0.117

Timeline

  • 2026-07-02: advisory: Initial advisory published by TR-CERT
  • 2026-07-02: disclosed: CVE-2026-4767 published

References

Related threats